WCU / Cybersecurity
~/CSC 472/Class 03
CSC 472 · Class 03

Buffer Overflows and Return-Address Hijacking

17 knowledge points. Work through them in order, or jump to any topic.

//

Knowledge Points

01Goal of Today → 02Ground Rules → 03What Is a Buffer Overflow? → 04The Usual Suspects (Unbounded Copies) → 05Stack Layout: buf, saved RBP, return address → 06Before vs. After the Overflow → 07Hijacking Control Flow → 08ret2win: Redirect to an Existing Function → 09The Payload = Padding + Target Address → 10Finding the Offset with Cyclic Patterns → 11Finding the Offset by Inspecting the Crash → 1232-bit vs. 64-bit Differences → 13The movaps Stack-Alignment Caveat (64-bit) → 14Vulnerable Functions Cheat-Sheet → 15Defenses Preview (full treatment in Class 05) → 16Tie-In to Lab 2 → 17Summary →